← Blog

Bangladesh's Data Law Has No Breach Notification—and Shwapno Proves It

Share on X

July 7, 2026: Bangladesh recently passed a data protection law. Unbelievably enough, it contains no mandatory breach notification requirement. There was nothing that required Shwapno—the country's largest supermarket chain—to tell you sooner when hackers walked away with four million customers' names, phone numbers, and purchase histories.

What happened to Shwapno

According to The Daily Star, intruders broke into Shwapno's customer database on August 19, 2025. They exfiltrated about 410 gigabytes of data covering roughly forty lakh (four million) registered shoppers. Attackers demanded $1.5 million in ransom. Shwapno refused, secured its systems, and—critically—said nothing to customers for seven months.

When the stolen archive surfaced on the dark web in March 2026, outrage spread across social media long before Shwapno filed a police report. Customers learned they were affected from posts and screenshots—not from the retailer they trusted with loyalty accounts and phone numbers tied to everyday grocery purchases.

What data was exposed

Investigative coverage describes the archive as operational retail intelligence, not anonymous statistics:

  • Customer names
  • Phone numbers (high-value for SMS phishing and SIM-swap chains in mobile-money ecosystems)
  • Purchase histories (patterns that enable targeted scams referencing recent orders)

Combined, these fields are enough to power convincing "your Shwapno order failed—click to refund" phishing and to cross-match identities against other leaked databases circulating in South Asian cybercrime markets.

Why Bangladesh's new law didn't help

The Daily Star's analysis of the Personal Data Protection Act framework highlights a structural gap: no mandatory breach notification. Without a legal clock forcing disclosure—72 hours, 30 days, or any fixed window—organizations can prioritize containment and brand protection over customer warning, especially when ransom negotiations fail and leaked data has not yet gone viral.

The same reporting connects Shwapno to a wider 2026 context: voter-list data sold openly on Facebook for as little as 30 taka, with penalties aimed at institutional controllers but no clear mechanism to hold individual resellers accountable. A law that cannot compel timely notice to breach victims—and struggles to reach informal data markets—leaves citizens discovering harm through Telegram forwards instead of regulated channels.

How this compares to other regimes

Mature privacy frameworks treat notification as non-negotiable:

  • GDPR (EU/EEA): controllers must notify supervisory authorities within 72 hours when feasible and communicate high-risk breaches to individuals without undue delay.
  • U.S. state laws: most require consumer notice within a defined window once personal information is compromised.
  • India DPDP (2023): moving toward board reporting and individual notice for significant breaches.

Bangladesh's omission is not a drafting footnote—it is the difference between learning in August 2025 and learning in March 2026 from strangers on the internet.

Who is at risk now

  • Shwapno loyalty and app users whose phone numbers anchor bKash/Nagad-adjacent social-engineering.
  • Households whose purchase history reveals income proxies, dietary or medical buying patterns, and delivery addresses in combined datasets.
  • Any Bangladeshi consumer whose data appears in parallel leaks (voter rolls, telecom marketing lists) that criminals merge with retail rows for higher conversion phishing.

Action items if you may be affected

  1. Assume exposure if you held a Shwapno registered account before August 2025—do not wait for an official letter that may arrive late or never.
  2. Enable transaction alerts on mobile banking and card apps; treat SMS about "failed Shwapno payments" as suspicious until verified out-of-band.
  3. Rotate passwords reused on Shwapno or linked email accounts; use a password manager and unique credentials per retailer.
  4. Watch for SIM-swap attempts targeting numbers in the leak—carrier PIN locks and number-transfer blocks reduce account-takeover risk.
  5. Do not download alleged leak archives from Telegram or forums; they are often poisoned with malware.

What policymakers and enterprises should do

Legislators can still amend implementing rules to add:

  • Mandatory victim notification with short statutory deadlines and public register filings.
  • Sanctions for unreasonable delay—Shwapno's seven-month silence would trigger fines in most OECD privacy regimes.
  • Clear accountability for informal resale of personal data on social platforms, not only for registered corporate controllers.

Retailers operating at Shwapno's scale should adopt notification playbooks before law forces them: pre-drafted customer messages, regulator contacts, and forensic retainers so August intrusions do not become March social-media scandals.

Canonical record

BreachHistory catalog entry: Shwapno customer database intrusion (2025–2026).

Primary source: The Daily Star — Why Bangladesh's new data protection law may fail to protect your data (July 7, 2026).